WordPress Lazy Content Slider Plugin 3.4 contains a cross-site request forgery vulnerability that allows attackers to perform unauthorized actions by crafting malicious HTML forms. Attackers can trick authenticated administrators into submitting POST requests to the plugin settings page via lzcs_admin.php to modify plugin configuration parameters like lzcs_color and lzcs_count.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-06-15 14:16
Updated : 2026-06-17 00:43
NVD link : CVE-2016-20074
Mitre link : CVE-2016-20074
CVE.ORG link : CVE-2016-20074
JSON object : View
Products Affected
No product.
CWE
CWE-352
Cross-Site Request Forgery (CSRF)
